Frogtastic
alkfljfjkpiccfgbeocbbjjladigcleg
Risk Score
4.33
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy hosted on cloudapi.stream CDN, not scoped to this extension, does not specify data collection — privacy pillar maxed.
- Uninstall URL hijack flag set — classic monetization shell telltale even with null target.
- jquery@3.2.1 bundles 3 medium CVEs (XSS); unfixed, version below fixed_in=3.5.0.
- Free-webmail dev (gmail), no developer name, no verified publisher — identity unverifiable.
- 10 external JS hosts referenced in CRX including goo.gl short-linker and unknown CDNs.
Evidence
- uninstall_url_hijack crx uninstall_url_hijack=true; target null but flag present — monetization shell indicator (+3.0 webstore).
- privacy_policy_not_scoped store Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=false, third_party_sharing=true → +9.0 base + capped at 10.
- free_webmail_no_dev_name store developer_email=nadejdinv@gmail.com, developer_name empty, no verified publisher → reputation floor 7.5.
- jquery_cve_medium_x3 crx jquery@3.2.1 has CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all medium, unfixed in bundled version).
- external_js_hosts_10 crx 10 distinct external hosts in js_external_hosts incl. goo.gl, bnjmnt4n.now.sh, cloudapi.stream.
- sandbox_csp_unsafe_eval manifest Sandbox CSP includes unsafe-inline and unsafe-eval on script-src — elevated XSS risk in sandbox context.
- install_url_hijack crx install_url_hijack=true, target=popup/index.html (internal) — lower risk but pattern matches shell.
- obfuscation_zero_code_clean crx obfuscation_score=0.0, code_findings_raw empty — no active exfil signals detected.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- uninstall_url_hijack high Extension sets uninstall URL redirect — a classic monetization/tracking shell signal.
- install_url_hijack medium onInstalled opens popup/index.html internally; low direct risk but confirms hijack pattern.
Pillar Scores
Permissions1.00
Reputation7.50
Network3.00
Webstore6.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:54
Listing SHA
9a642df76e2b…
Force block
— not fired
Score recovered
no
Elapsed
—